Online Privacy and Your Data Who Knows What About You, and What You Can Do About It

Almost everything you do online leaves a trail, and a large industry exists to collect it. This guide explains how it works, what the law says and what you can do about it.

Technology & Digital Life

↓
Chapter I

Who Collects Your Data and Why The Economy Behind the Screen

Every time you search, shop, scroll, travel with a phone or use a loyalty card, you generate data. Companies collect it because it has commercial value, and understanding why is the first step towards managing it.

Many online services are free to use because they earn money from advertising, which is more valuable when it is targeted. To target it, companies gather information about your interests, location, device, browsing, purchases and sometimes your relationships, and combine it into a profile. Data brokers collect and sell such information, often without individuals knowing. Data is also collected through cookies and trackers on websites, apps that share information with third parties and devices such as smart speakers, TVs and doorbells.

This is not always harmful, and sometimes the exchange is worthwhile. Personalised recommendations, free maps and email are genuine benefits. But there are risks: data can be breached and used by criminals for fraud, it can be used to influence what you see and the prices you are offered, and it can reveal sensitive information, such as health, finances or beliefs, that you might wish to keep private. The aim is not to disappear from the internet but to make informed choices.

If a service is free, you are often paying with your attention and your data. That is not always a bad deal, but you should know that you are making it.

· · ·
Chapter II

Your Rights in the UK Data Protection Law Explained

Data protection law in the UK gives you real, enforceable rights over how organisations handle your personal data.

The UK General Data Protection Regulation and the Data Protection Act 2018 set rules for organisations that collect and use personal data. They must have a lawful reason, tell you what they are doing, collect only what is needed, keep it secure and not hold it longer than necessary. You have rights, including the right to be told how your data is used, the right to see a copy of the data held about you, known as a subject access request, the right to have inaccurate data corrected, the right to have data erased in certain circumstances, the right to object to direct marketing and the right to restrict or object to some processing. Organisations normally have one month to respond to a request.

To use your rights, write or email the organisation's data protection officer or privacy contact, whose details are in the privacy policy, and say what you want. Keep a copy. If they do not respond properly, you can complain to the Information Commissioner's Office, the UK regulator, which has guidance and a complaints process on its website. You can also seek a remedy through the courts in some circumstances.

Cookies on websites are covered by separate privacy rules, which generally require consent for non-essential cookies, such as those used for advertising. Cookie banners should make it as easy to reject cookies as to accept them, though in practice some are designed to nudge you towards accepting.

· · ·
Chapter III

Privacy Settings That Matter A Ten-Minute Tune-Up for Your Accounts

Default settings favour the company, not you. A short review can reduce what you share.

Start with your phone. Review which apps have access to location, microphone, camera, contacts and photographs, and revoke permissions that are not needed. Both Apple and Google provide privacy dashboards that show recent access. Switch off personalised ad tracking and limit ad tracking across apps. Turn off location history if you do not use it, and check which apps use your precise location.

Move to your main accounts. In your Google, Apple, Microsoft and Meta account settings, you can review and delete activity history, turn off ad personalisation and adjust what is saved. In social media, set your profile to private or limit who can see your posts, who can tag you and who can find you by phone number or email. Review old posts, and consider deleting what you would not want a stranger or an employer to see.

In your browser, block third-party cookies, review site permissions and consider a privacy-focused browser or extensions that block trackers. Clear your browsing data from time to time. Private or incognito mode stops your browser storing history on your device, but it does not hide your activity from websites, employers or your internet provider.

Photographs Carry Data

Photographs taken with a phone may contain hidden information called metadata, including the time, the device and the exact location. Many platforms strip it when you post, but not all. Turn off location tagging on your camera if you do not need it.

· · ·
Chapter IV

Cutting Down on Tracking and Marketing Reducing Junk, Calls and Profiling

You cannot eliminate tracking, but you can reduce it significantly.

Use the marketing preferences in your accounts. When you sign up to a service, untick the boxes that agree to marketing and sharing with partners, and use the unsubscribe links in genuine marketing emails. Do not click unsubscribe in spam, which confirms your address is live. Register with the Telephone Preference Service and the Mailing Preference Service to reduce unsolicited calls and post, and the Fundraising Preference Service to limit charity contact. These do not stop scammers, who ignore the rules, but they reduce legitimate cold calling.

Consider using different email addresses. A separate address for shopping and newsletters keeps your main inbox cleaner and makes it easier to spot where a leak has come from. Some email services offer aliases that forward to your main address, which can be switched off if they attract spam. Think carefully before giving your phone number, date of birth or home address to businesses, and ask why it is needed. You are entitled to question requests for information that appears unnecessary.

Be thoughtful about loyalty cards and quizzes. Cards that offer discounts in return for tracking your purchases are a trade-off, and the amount of data that you give is often more valuable than the discount. Online quizzes and viral apps that ask for personal details can be used to harvest information for scams.

· · ·
Chapter V

Data Breaches and Deleting Your Footprint Responding to Leaks and Tidying Up

Data breaches are now common, and almost everyone has been affected at some point. What matters is what you do next.

If an organisation informs you of a breach, read the message carefully, checking that it is genuine through its official website. Change your password for that service and any other where you used the same one. Switch on two-step verification. Watch for phishing emails and texts that use the leaked information, as criminals often follow a breach with convincing scams. If financial details were involved, contact your bank. If your identity documents were exposed, consider a credit report check with the main credit reference agencies, and a protective registration with a service such as Cifas, which helps to prevent fraudulent applications in your name.

Reduce your footprint. Delete accounts that you no longer use, since each one is a potential source of a leak. Many services have a delete my account option in settings, and you have the right to request erasure under data protection law. Remove old apps and unsubscribe from lists. Search for your own name from time to time to see what appears, and request removal of outdated or harmful content where possible. Search engines in the UK offer a process for requesting delisting of certain results.

Keep Learning

The Information Commissioner's Office and the National Cyber Security Centre publish free, plain-English guidance on protecting your data.

· · ·
Chapter VI

Privacy for Families and Homes Children, Smart Devices and Sharing About Others

Privacy is not only a personal matter. Parents, homeowners and anyone who posts about other people have responsibilities as well.

Children generate data from the earliest age, through school apps, games, social media and the photographs that adults post about them. Think before sharing photographs and information about your children online, since they cannot consent and may live with the digital trail for decades. Use privacy settings, share with limited audiences and avoid posting identifying details such as the school uniform, location or full names. Talk to older children about their own footprints.

Smart devices, such as speakers, TVs, doorbells and cameras, can listen, watch and collect data. Choose reputable brands, change default passwords, review the privacy settings and consider where they are positioned. If you use a camera that captures areas beyond your property, such as a neighbour's garden or a public street, data protection rules may apply, and you should follow the guidance of the Information Commissioner's Office, including signs and sensible limits.

Consider the privacy of others. Ask before posting photographs of friends or sharing screenshots of private conversations. Be careful about tagging people and checking in at places with others. A bit of courtesy goes a long way.

A Privacy Habit

Once a year, review the settings on your phone and main accounts, delete accounts you no longer use and check what appears when you search for your name.

· · ·
Subscribe for Full Access